GhostDNS: 70+ different types of home routers (100,000+) are being hijacked
Over a 100K routers from brands like D-Link, MikroTik, TP-Link, Huawei and SpeedTouch are currently hijacked and have a changed the DNS server. That way traffic can be re-routed ending up at phishing sites etc.
While not a new methodology, from the 20th of September of this year a large attack was discovered by security researchers. So basically on a malicious website, a script would be executed that sniffs if your router port is open, try to log in (brute force) to your router, that changes credentials and DNS. A lot of users use the default username and password which makes them extra vulnerable. Once the criminals are able to login they change the DNS server address of the router. Currently, the attacks are mainly active in Brazil.
The current attack, discovered by network security lab 360 Netlab, affects more than 70 different routers:
- 3COM OCR-812
- AP-ROUTER
- D-LINK
- D-LINK DSL-2640T
- D-LINK DSL-2740R
- D-LINK DSL-500
- D-LINK DSL-500G/DSL-502G
- Huawei SmartAX MT880a
- Intelbras WRN240-1
- Kaiomy Router
- MikroTiK Routers
- OIWTECH OIW-2415CPE
- Ralink Routers
- SpeedStream
- SpeedTouch
- Tenda
- TP-LINK TD-W8901G/TD-W8961ND/TD-8816
- TP-LINK TD-W8960N
- TP-LINK TL-WR740N
- TRIZ TZ5500E/VIKING
- VIKING/DSLINK 200 U/E
In total, more than 100,000 routers are affected by the attack of which the majority is located in Brazil. As soon as the users browse to specific websites they are redirected to phishing sites. These include online banking sites but also Netflix and hosting companies.
Once again, make sure your router firmware is up-to-date, disable external WAN access, and change your default password.
Senior Member
Posts: 813
Joined: 2009-11-30
What a day we live in today..... So many hardware/software vulnerabilities out there its simply amazing anything is up and running ATM. Anything......
Just crazy.....!!
well ATM basically LAN (enclosed-wan) that only connect to banking-network
which separate them from internet-open-world
thats why they not effected much by real-world vulnerabilites... even though probably they share same vulnerabilites
Senior Member
Posts: 823
Joined: 2006-02-05
Think he ment 'At The Moment' xD
Senior Member
Posts: 2270
Joined: 2011-05-19
Thanks Ron Burgundy! now i know why you're the most trusted name in San Diego!
Senior Member
Posts: 101
Joined: 2014-02-01
and lo ~ I have a router update! thnx for the heads up! (even updated just a month ago).
if anyone needs help do this:
open file explorer (the folder icon on the taskbar)
click "network" on the left
in windows 10, my wifi router appears under "network infrastructure" as "R7000 (Gateway)"
right click that > "view device webpage"
if it's netgear, The user name is admin, and the password is password
you may see a flag to update firmware at the top of that main page, if not,
click "advanced" tab > click "administration" on the left > "router update"
again, you should see update firmware, but if not click "check"
let it take the time to update and reset your router (no internet for a minute while it resets)
as for your cable modem, google your device model number. if it's like mine, it says that firmware updates are pushed by your ISP so no worries there

other tips to maximize security:
- there may be an option to auto update on your router page (expect to be kicked offline sometimes but who knows maybe it's smarter and knows your idle time like windows 10 updates now)
- keep windows up to date (type 'check for updates' on windows 10 search bar) > click "check now" if they don't appear already
- keep your pc up to date w/ manufacturer software (for me it's the "Lenovo vantage" windows 10 app. this pc updates its bios etc a lot)
- use a wired connection directly from your cable modem to your newest PC (a new chipset that's designed to not have spectre and meltdown vulnerabilities etc).
Senior Member
Posts: 1149
Joined: 2011-01-11
What a day we live in today..... So many hardware/software vulnerabilities out there its simply amazing anything is up and running ATM. Anything......
Just crazy.....!!